|
|
|
![]() |
Vulnerability Note VU#260421Squid fails to parse empty access control lists correctlyOverviewThe Squid web proxy cache may fail to handle empty Access Control Lists (ACLs) in the intended manner.I. DescriptionSquid functions as a web proxy and cache application for a number of protocols. However, Squid Access Control List (ACL) routines may not parse an empty list as intended. An empty list may be interpreted as a nonexistent list rather than a list containing no members. This may or may not be the intended behavior.II. ImpactUnintended access may be granted to all members instead of the intended result of access being denied to all members.III. SolutionApply an updateThis flaw has been patched in Squid 2.5.STABLE8. More details are available in the Squid Bugzilla bug #1166. Pay attention to warnings from "squid -k parse" and do not use configurations where there are warnings about access controls in production. Systems Affected
References
Thanks to Team Squid for reporting this vulnerability. This document was written by Ken MacInnis.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||